ISC2 Certified Cloud Security Professional (CCSP) Practice Question
Your organization is migrating its finance analytics platform to a public IaaS provider. Management requires that backups stored in object storage remain confidential while at rest, that separation of duties prevents the cloud provider's administrators from accessing plaintext data, and that the organization can perform a cryptographic erase when the contract ends. Which design approach BEST meets all three requirements?
Apply data masking to sensitive fields before backup and forego encryption to reduce key-management overhead.
Enable server-side encryption using provider-managed keys and rely on object storage versioning for recovery.
Store backups as block-level snapshots in a segregated virtual network and restrict access with IAM policies only.
Encrypt data client-side with keys generated and stored in the organization's on-premises HSM and upload ciphertext backups.
Client-side encryption ensures that data is encrypted before it enters the provider's environment, so only ciphertext is stored in the object store. Generating and retaining the master keys in an on-premises hardware security module (HSM) enforces strict separation of duties, because provider administrators never have access to the keys. Because the customer exclusively controls the keys, they can delete them at contract termination, achieving cryptographic erasure. Provider-managed keys cannot guarantee provider inaccessibility, snapshots alone do not deliver encryption or crypto-erase capability, and simple data masking leaves confidential values recoverable from the backups.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is client-side encryption and how does it differ from server-side encryption?
Open an interactive chat with Bash
What is a hardware security module (HSM) and why is it used in secure key management?
Open an interactive chat with Bash
What is cryptographic erasure and how does it achieve data confidentiality?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Concepts, Architecture and Design
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .